DEMO · labelled fixtures · no authoritative writes
Sovereign identity security for Africa and beyond

A FluxCore identity platform

Secure every
identity.

From employees and customers to devices and AI agents, StratoID puts access, governance and endpoint trust in one sovereign control plane.

Create demo workspace

Labelled browser fixtures · No provider or device writes · Not GA

ACCESS DECISIONVERIFIEDidentity + device + risk
01HUMAN
IDENTITY
02DEVICE
TRUST
03AI AGENT
SCOPE

IDENTITY IS THE CONTROL PLANE

Protect every identity.
No exceptions.

StratoID follows trust across the full lifecycle—before sign-in, during access and after the session ends.

01

Workforce identity

People get productive. Access stays precise.

Unify employees and contractors with passwordless SSO, adaptive MFA and automated joiner-mover-leaver workflows.

02

Customer & partner identity

Trusted access, shaped around your brand.

Create branded tenant realms, inbound enterprise federation, secure registration and privacy-aware account controls.

03

Device identity

Every endpoint proves it belongs.

Bind access to enrolled laptops, phones, Wi-Fi, VPN and Linux devices with posture signals that follow every decision.

04

Non-human identity

AI agents & service identities, governed.

Issue tenant-aware machine credentials with narrow scopes, short lifetimes and no standing refresh access.

THE STRATOID PLATFORM

One fabric.
Two powerful experiences.

01 / SECURE THE ORGANISATION

Workforce
Identity Cloud

Secure employees, contractors, devices, applications and networks with one context-aware policy plane.

  • End-to-end identity visibility
  • Adaptive access and phishing-resistant MFA
  • Lifecycle, governance and audit evidence
Open the workforce console
02 / BUILD TRUSTED EXPERIENCES

External
Identity Cloud

Give customers, partners, AI agents and service clients secure access without sacrificing speed or brand control.

  • Branded, multi-tenant identity realms
  • Enterprise federation and scoped APIs
  • Privacy-aware registration and recovery
Explore external identity

106 ADVERTISED OPERATIONS

A broad surface.
Truthfully classified.

Explore 16 interactive capability domains. Their release states vary; the public demo is not production evidence.

ID01

Tenants & Users

Multi-tenant provisioning, user directory, group membership.

8 operations
AU02

Auth, Sessions & M2M

Token issuance, refresh/revoke, registration, password reset, device sessions, service clients.

13 operations
LD03

Cloud LDAP

A hosted LDAP directory — no VM, no patching, no FreeIPA ops burden.

4 operations
RA04

RADIUS

Cloud RADIUS for Wi-Fi and VPN — NAS clients, MFA-gated authorization.

4 operations
SS05

SSO Applications

SAML + OIDC app catalog — metadata, assertions, one identity for every app.

6 operations
MF06

Multi-Factor Auth

TOTP enrollment/activation, verification, backup codes, factor management.

11 operations
AP07

Access Policies

Password strength, conditional access (Zero Trust), local-account / sudo mapping.

9 operations
DT08

Device Management

Reference device workflows across five platforms — real OS management remains externally blocked.

7 operations
CP09

Config Profiles

FileVault, BitLocker, Wi-Fi, passcode, USB-restriction — assigned by group, device or platform.

4 operations
DL10

Data Loss Prevention

External storage / AirDrop / personal-cloud controls, authorized drives, event stream.

5 operations
SK11

SSH Keys

Per-user SSH key management, projected as authorized_keys for enrolled Linux devices.

4 operations
PM12

Patch Management

OS + third-party patch policies, catalog, per-device status, one-click remediation.

5 operations
IN13

Integrations

Simulated Google, M365, AWS, Git and Kubernetes connector records; live reconciliation is not released.

5 operations
IG14

Identity Governance

Entitlement catalog, time-bound access, independent approvals, revocation and certification evidence.

12 operations
AD15

Artifact Discovery

Safe metadata-only repository analysis, software identity, SBOM/signing evidence and readiness scoring.

4 operations
CE16

Command & Evidence

Natural-language plans with exact actions, dry runs, approvals, rollback and tenant-scoped audit evidence.

5 operations

SEE THE CONTROL PLANE

One identity journey.
Four connected moments.

Follow how StratoID combines lifecycle, authentication, device posture and audit evidence instead of handing them to disconnected tools.

Lifecycle automation

Revoke access everywhere in one move

Explore an illustrative leaver sequence; downstream provider deprovisioning is simulated in this demo.

Open user lifecycle
Illustrative sequenceLive
DEMOno provider writes
Sessions & tokensFixtureSimulated
M365 · Slack · GitHubFixtureSimulated
Managed devicesFixtureNo device

EXTENSIBLE BY DESIGN

Your technology stack already has a seat.

Synchronise directories, provision downstream applications and enforce the same trust decision across cloud and network infrastructure.

Explore simulated integrations
token-request.sh
curl -X POST \
https://id.example.ng/oauth/token \
-d grant_type=client_credentials \
-d scope="directory:read devices:read"

# 15-minute, tenant-scoped token
{
"token_type": "Bearer",
"expires_in": 900
}

BUILT FOR BUILDERS

Standards first.
No identity detour.

Connect applications, automate operations and issue machine credentials through familiar protocols and tenant-scoped APIs.

  • OIDC, OAuth 2.1, SAML 2.0 and SCIM
  • Short-lived service and AI-agent credentials
  • OpenAPI-defined product operations
Open developer controls

ENGINEERED AS A CONTROL PLANE

Targets you can test.
Evidence you can keep.

StratoID makes its critical identity-path objectives explicit, so availability, revocation and auditability can be designed and verified.

99.99%token-path availability target
≤250 msP99 token issuance target
≤30 secglobal deactivation contract
7 yearsappend-only audit retention

PRODUCTION BOUNDARY DESIGN

Security controls implemented; real-environment proof pending.

01

Authentication

Authentik is the selected production issuer; deployment and conformance evidence is pending.

02

Authorisation

SpiceDB adapters and deny-by-default checks are implemented; deployed tuple evidence is pending.

03

Secrets

Vault Transit adapters protect server-held sessions and audit signatures when real infrastructure is supplied.

04

Evidence

Durable audit/outbox code exists; SIEM export, recovery and operational evidence remain blockers.

RELEASE STATUS · NO-GO FOR GA

Interactive demo.
Not a production deployment.

Connectors, real OS management, signed mobile releases, the network data plane, multi-region recovery, load, accessibility and independent security evidence remain blocked. Capability states and owners are tracked in the repository.

Read current limitations

READY WHEN YOU ARE

Make identity your
strongest control.

Explore the reference workflows, evidence boundaries and current capability states.

Create demo account